diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index f894f60d5b2..fcc25cd508a 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8eff6279f5da2ba7608a503707e2d33445ee0f296b248a1d9a6871a379620e84","body_hash":"a5dd2caf5941d60224e3ac3a0c9fd629d68d6732d61a708364dc851c3dc46425","strict":true,"agent_id":"codex","agent_model":"gpt-5.4","engine_versions":{"codex":"0.144.6"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8eff6279f5da2ba7608a503707e2d33445ee0f296b248a1d9a6871a379620e84","body_hash":"ca1cef62a86074fb44791b0a09bd6e04a1bfa8694ab055d64fee6d54c053b32e","strict":true,"agent_id":"codex","agent_model":"gpt-5.4","engine_versions":{"codex":"0.144.6"}} # gh-aw-manifest: {"version":1,"secrets":["CODEX_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN","OPENAI_API_KEY"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"docker/build-push-action","sha":"53b7df96c91f9c12dcc8a07bcb9ccacbed38856a","version":"v7.3.0"},{"repo":"docker/setup-buildx-action","sha":"bb05f3f5519dd87d3ba754cc423b652a5edd6d2c","version":"v4.2.0"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.37","digest":"sha256:1d5300d9b08e1c4f2ad1830860656a0656383a83280058f17e805a7c3ecda203","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.37@sha256:1d5300d9b08e1c4f2ad1830860656a0656383a83280058f17e805a7c3ecda203"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.3","digest":"sha256:3c744710ea275cd5ee65db92a1099e0d980754bd9fafda9ce67704c67004dc83","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.3@sha256:3c744710ea275cd5ee65db92a1099e0d980754bd9fafda9ce67704c67004dc83"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/daily-observability-report.md b/.github/workflows/daily-observability-report.md index cf72ff7bf88..e53d15230e4 100644 --- a/.github/workflows/daily-observability-report.md +++ b/.github/workflows/daily-observability-report.md @@ -140,9 +140,10 @@ The AWF Firewall uses Squid proxy for egress control. The key log file is `acces For each firewall-enabled workflow run, check: -1. **access.log existence**: Look for `access.log/` directory in the run logs - - Path pattern: `/tmp/gh-aw/aw-mcp/logs/run-/access.log/` - - Contains files like `access-*.log` +1. **access.log existence**: Search recursively inside each run folder for firewall access logs + - Canonical path: `/tmp/gh-aw/aw-mcp/logs/run-/sandbox/firewall/logs/access.log` + - Also accept equivalent paths nested under artifact-prefixed directories (workflow_call) + - Do not assume a fixed top-level location; use recursive discovery 2. **access.log content quality**: - Are there log entries present? @@ -174,14 +175,21 @@ The MCP Gateway logs tool execution. Two log formats may be present depending on For each run that uses MCP servers, check in this order: -1. **gateway.jsonl existence** (preferred): Look for the file in run logs - - Path pattern: `/tmp/gh-aw/aw-mcp/logs/run-/mcp-logs/gateway.jsonl` +1. **gateway.jsonl existence** (preferred): Search recursively inside the run folder + - Canonical path: `/tmp/gh-aw/aw-mcp/logs/run-/mcp-logs/gateway.jsonl` + - Also accept equivalent paths nested under artifact-prefixed directories (workflow_call) 2. **rpc-messages.jsonl existence** (canonical fallback): Check when gateway.jsonl is missing - - Path pattern: `/tmp/gh-aw/aw-mcp/logs/run-/mcp-logs/rpc-messages.jsonl` + - Canonical path: `/tmp/gh-aw/aw-mcp/logs/run-/mcp-logs/rpc-messages.jsonl` + - Also accept equivalent paths nested under artifact-prefixed directories (workflow_call) - This file is written by the Copilot CLI and contains raw JSON-RPC protocol messages - A run with this file present has MCP telemetry and should NOT be reported as Critical +**Path normalization rule (required):** +- For each run, determine telemetry presence by recursively finding files named `gateway.jsonl` or `rpc-messages.jsonl` anywhere under `run-/`. +- Record the exact discovered path(s) in your analysis notes before assigning status. +- Never classify a run as "missing MCP telemetry" based only on one hardcoded path check. + 3. **gateway.jsonl content quality** (when present): - Are log entries valid JSONL format? - Do entries contain required fields: